This document is a security advisory regarding the CODESYS (Edge) Gateway for Windows, specifically addressing vulnerabilities related to its insecure default configuration. The advisory outlines that the CODESYS Gateway facilitates communication between CODESYS runtimes and clients but is accessible remotely by default, which poses security risks. It identifies affected products and provides vulnerability identifiers, including CVE-2024-41975 and a CVSS score indicating medium severity. The advisory emphasizes the importance of updating to version 3.5.21.0 to mitigate these vulnerabilities. It details remediation steps, including uninstallation of previous setups and configuration adjustments to restrict remote access. Additionally, it offers general security recommendations to enhance protection, such as using firewalls, encrypted communication, and user management. The document concludes with acknowledgments and a disclaimer regarding liability for the information provided.